system is under attack (what can I do more?)

2010-06-18 Thread Dino Vliet
Dear freebsd list, My server, which is a amd64 system running freebsd 8.0 is currently under attack from a botnet or something. Take a look at my /var/log/auth.log file: Jun 18 12:00:00 dual newsyslog[34486]: logfile turned over due to size100K Jun 18 12:00:44 dual sshd[34500]: Address

Re: system is under attack (what can I do more?)

2010-06-18 Thread Balázs Mátéffy
Hello, 1, maybe the line with the rule is in a bad place in the conf, but even if it's working it's possible that it wont be triggered. As far as I can see there are 30 sec interval pauses between attacks from one host. Your rule is looking for connections in 30 sec ranges. 2,You should use a

Re: system is under attack (what can I do more?)

2010-06-18 Thread Bruce Cran
On Friday 18 June 2010 13:23:27 Dino Vliet wrote: Dear freebsd list, My server, which is a amd64 system running freebsd 8.0 is currently under attack from a botnet or something. Take a look at my /var/log/auth.log file: [...] I looked at this and especially the way they seem to try

Re: system is under attack (what can I do more?)

2010-06-18 Thread Jerry Bell
On 6/18/2010 8:23 AM, Dino Vliet wrote: 2) are there other things I could do? Brgds Dino Look at ports/security/sshguard and ports/security/bruteblock. I use sshguard with ipfilter, but it works with pf and ipfw as well. It is very simple to set up and gets the job done. Jerry

Re: system is under attack (what can I do more?)

2010-06-18 Thread Kaya Saman
[...] Look at ports/security/sshguard and ports/security/bruteblock. I use sshguard with ipfilter, but it works with pf and ipfw as well. It is very simple to set up and gets the job done. Jerry ___ freebsd-questions@freebsd.org mailing list

Re: system is under attack (what can I do more?)

2010-06-18 Thread Glen Barber
Hi, On 6/18/10 11:29 AM, Kaya Saman wrote: [...] Look at ports/security/sshguard and ports/security/bruteblock. I use sshguard with ipfilter, but it works with pf and ipfw as well. It is very simple to set up and gets the job done. Hi just wanted to say thanks for stating this as I'm also

Re: system is under attack (what can I do more?)

2010-06-18 Thread Kaya Saman
On 18/06/2010 18:48, Glen Barber wrote: Hi, On 6/18/10 11:29 AM, Kaya Saman wrote: [...] Look at ports/security/sshguard and ports/security/bruteblock. I use sshguard with ipfilter, but it works with pf and ipfw as well. It is very simple to set up and gets the job done. Hi just wanted to

Re: system is under attack (what can I do more?)

2010-06-18 Thread Jason Dixon
On Fri, Jun 18, 2010 at 11:48:25AM -0400, Glen Barber wrote: Hi, On 6/18/10 11:29 AM, Kaya Saman wrote: [...] Look at ports/security/sshguard and ports/security/bruteblock. I use sshguard with ipfilter, but it works with pf and ipfw as well. It is very simple to set up and gets the job

Re: system is under attack (what can I do more?)

2010-06-18 Thread Greg Larkin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Kaya Saman wrote: On 18/06/2010 18:48, Glen Barber wrote: Hi, On 6/18/10 11:29 AM, Kaya Saman wrote: [...] Look at ports/security/sshguard and ports/security/bruteblock. I use sshguard with ipfilter, but it works with pf and ipfw as well. It

Re: system is under attack (what can I do more?)

2010-06-18 Thread Matthias Fechner
Am 18.06.10 17:55, schrieb Jason Dixon: Doesn't FreeBSD's version of pf support the overload feature? This is how we typically manage ssh bruteforce attempts in OpenBSD/pf-land. and what you want to do if a user connects authorizied very often in lets say 10 seconds? If you work e.g. with

Re: system is under attack (what can I do more?)

2010-06-18 Thread Matthew Seaman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 18/06/2010 16:55:14, Jason Dixon wrote: Doesn't FreeBSD's version of pf support the overload feature? This is how we typically manage ssh bruteforce attempts in OpenBSD/pf-land. Sure it does. pf in FreeBSD 7.2+ or 8.0+ is basically the same as

Re: system is under attack (what can I do more?)

2010-06-18 Thread Kaya Saman
On 06/18/2010 06:59 PM, Greg Larkin wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Kaya Saman wrote: On 18/06/2010 18:48, Glen Barber wrote: Hi, On 6/18/10 11:29 AM, Kaya Saman wrote: [...] Look at ports/security/sshguard and ports/security/bruteblock. I